Re: Po restartu, vše jak před dvěma dny... pls. Help
Napsal: 10 dub 2010 12:29
Ten soubor neznám.. s tím CF je problém v tom že restartuje PC a po něm je vše jako před tím.... a žádný log se neuloží
Pomáháme v boji s počítačovou havěti!
https://forum.viry.cz:443/
Kód: Vybrat vše
>[/color]
[color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >[/color]
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008/04/14 03:52:18 | 000,040,448 | ---- | M] (Microsoft Corporation)
"EA Core" = "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent -- File not found
"ICQ" = "C:\Program Files\ICQ6.5\ICQ.exe" silent -- File not found
"RGSC" = C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent -- [2010/01/24 06:32:19 | 000,306,088 | ---- | M] (Take-Two Interactive Software, Inc.)
[color=#A23BEC]< c:\windows\*.* /U >[/color]
[5 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
Invalid Environment Variable: %ALLUSERSPROFILE%\Application Data\*.
Invalid Environment Variable: %ALLUSERSPROFILE%\Application Data\*.exe
Invalid Environment Variable: %APPDATA%\*.
Invalid Environment Variable: %APPDATA%\*.exe
[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 19:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 19:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 19:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 18:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 18:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 17:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[color=#A23BEC]< MD5 for: CHANGER.SYS >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008/04/13 19:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[color=#A23BEC]< MD5 for: CRYPTSVC.DLL >[/color]
[2004/08/17 08:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008/04/14 03:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008/04/14 03:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color]
[2008/04/14 03:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 03:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004/08/17 08:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2008/04/14 03:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\NiwradSoft Shell Pack\Backup\explorer.exe
[2004/08/17 08:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008/04/14 03:52:24 | 001,541,120 | ---- | M] (Microsoft Corporation) MD5=D63C59BB0CA2F83B62D003FD52863090 -- C:\WINDOWS\explorer.exe
[2008/04/14 03:52:24 | 001,541,120 | ---- | M] (Microsoft Corporation) MD5=D63C59BB0CA2F83B62D003FD52863090 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[color=#A23BEC]< MD5 for: HAL.DLL >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008/04/13 19:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008/04/13 19:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2004/08/03 15:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
[color=#A23BEC]< MD5 for: IASTOR.SYS >[/color]
[2009/12/19 09:42:37 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\WINDOWS\NLDRV\001\iastor.sys
[2009/12/19 09:42:37 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\WINDOWS\system32\drivers\iaStor.sys
[color=#A23BEC]< MD5 for: ISAPNP.SYS >[/color]
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2001/10/24 06:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2001/10/25 09:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\isapnp.sys
[2008/04/14 02:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008/04/14 01:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2008/04/14 01:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008/04/14 02:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\ReinstallBackups\0019\DriverFiles\i386\isapnp.sys
[color=#A23BEC]< MD5 for: LSASS.EXE >[/color]
[2004/08/17 08:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008/04/14 03:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008/04/14 03:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2008/04/13 19:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008/04/13 19:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004/08/03 16:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
[2004/08/17 08:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008/04/14 03:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 03:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
[2004/08/17 08:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 03:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 03:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[color=#A23BEC]< MD5 for: SMSS.EXE >[/color]
[2004/08/17 08:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008/04/14 03:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008/04/14 03:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
[2008/04/14 03:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 03:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004/08/17 08:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[color=#A23BEC]< MD5 for: TCPIP.SYS >[/color]
[2008/04/13 19:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008/04/13 19:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008/06/20 07:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008/06/20 07:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004/08/03 16:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008/06/20 07:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2008/04/14 03:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 03:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004/08/17 08:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2004/08/17 08:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 03:52:54 | 000,547,328 | ---- | M] (Microsoft Corporation) MD5=471341D353962A35DA3C6324D59D09C4 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 03:52:54 | 000,547,328 | ---- | M] (Microsoft Corporation) MD5=471341D353962A35DA3C6324D59D09C4 -- C:\WINDOWS\system32\winlogon.exe
[2008/04/14 03:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\NiwradSoft Shell Pack\Backup\winlogon.exe
[color=#A23BEC]< MD5 for: WS2_32.DLL >[/color]
[2004/08/17 08:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008/04/14 03:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008/04/14 03:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[2008/06/20 13:49:25 | 000,147,968 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dnsapi.dll
[2008/04/14 03:51:50 | 000,378,880 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\mstask.dll
[2008/04/14 03:51:52 | 000,067,072 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\ntdsapi.dll
[2010/03/10 00:43:10 | 001,510,400 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shdocvw.dll
[2008/06/17 15:02:56 | 015,063,040 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shell32.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]
[color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]
[color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
[2009/12/19 15:10:51 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/12/19 15:10:51 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/12/19 15:10:51 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[2008/06/20 13:49:25 | 000,147,968 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dnsapi.dll
[2008/04/14 03:51:50 | 000,378,880 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\mstask.dll
[2008/04/14 03:51:52 | 000,067,072 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\ntdsapi.dll
[2010/03/10 00:43:10 | 001,510,400 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shdocvw.dll
[2008/06/17 15:02:56 | 015,063,040 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shell32.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[color=#A23BEC]< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >[/color]
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< End of report >
[color=#A23BEC]< MD5 for: [2001/10/24 06:44:12 | 000,035,840 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2001/10/24 06:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[color=#A23BEC]< MD5 for: [2001/10/25 09:00:00 | 000,035,840 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2001/10/25 09:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\isapnp.sys
[color=#A23BEC]< MD5 for: [2004/08/03 15:59:14 | 000,134,400 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/03 15:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
[color=#A23BEC]< MD5 for: [2004/08/03 16:14:30 | 000,182,912 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/03 16:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[color=#A23BEC]< MD5 for: [2004/08/03 16:14:42 | 000,359,040 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/03 16:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[color=#A23BEC]< MD5 for: [2004/08/03 17:59:44 | 000,095,360 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/03 17:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:04 | 000,060,416 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:08 | 000,055,808 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:14 | 000,407,040 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:18 | 000,184,832 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:22 | 000,082,944 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:24 | 000,013,312 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:24 | 001,032,704 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:28 | 000,014,336 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:28 | 000,024,576 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:28 | 000,050,688 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[color=#A23BEC]< MD5 for: [2004/08/17 08:49:28 | 000,502,272 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2004/08/17 08:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[color=#A23BEC]< MD5 for: [2008/04/13 18:10:32 | 000,096,512 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 18:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 18:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\atapi.sys
[color=#A23BEC]< MD5 for: [2008/04/13 19:01:30 | 000,134,400 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 19:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\HAL.DLL
[color=#A23BEC]< MD5 for: [2008/04/13 19:01:34 | 000,105,344 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 19:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[color=#A23BEC]< MD5 for: [2008/04/13 19:06:40 | 000,042,368 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 19:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 19:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\agp440.sys
[color=#A23BEC]< MD5 for: [2008/04/13 19:10:32 | 000,096,512 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 19:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[color=#A23BEC]< MD5 for: [2008/04/13 19:11:00 | 000,008,192 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 19:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[color=#A23BEC]< MD5 for: [2008/04/13 19:50:18 | 000,361,344 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 19:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008/04/13 19:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[color=#A23BEC]< MD5 for: [2008/04/13 19:50:38 | 000,182,656 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/13 19:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008/04/13 19:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ndis.sys
[color=#A23BEC]< MD5 for: [2008/04/14 01:57:54 | 000,037,248 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 01:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2008/04/14 01:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\isapnp.sys
[color=#A23BEC]< MD5 for: [2008/04/14 02:57:54 | 000,037,248 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 02:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008/04/14 02:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ReinstallBackups\0019\DriverFiles\i386\isapnp.sys
[color=#A23BEC]< MD5 for: [2008/04/14 03:51:40 | 000,062,464 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008/04/14 03:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cryptsvc.dll
[color=#A23BEC]< MD5 for: [2008/04/14 03:51:42 | 000,056,320 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 03:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
[color=#A23BEC]< MD5 for: [2008/04/14 03:51:52 | 000,407,040 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 03:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\netlogon.dll
[color=#A23BEC]< MD5 for: [2008/04/14 03:51:56 | 000,185,856 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 03:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:08 | 000,082,432 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008/04/14 03:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ws2_32.dll
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:24 | 001,034,240 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\NiwradSoft Shell Pack\Backup\explorer.exe
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:24 | 001,541,120 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:24 | 001,541,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2008/04/14 03:52:24 | 001,541,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:30 | 000,013,312 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008/04/14 03:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lsass.exe
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:48 | 000,050,688 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008/04/14 03:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\smss.exe
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:50 | 000,014,336 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 03:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:52 | 000,026,112 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 03:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\userinit.exe
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:54 | 000,507,904 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\NiwradSoft Shell Pack\Backup\winlogon.exe
[color=#A23BEC]< MD5 for: [2008/04/14 03:52:54 | 000,547,328 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/04/14 03:52:54 | 000,547,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 03:52:54 | 000,547,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winlogon.exe
[color=#A23BEC]< MD5 for: [2008/06/20 07:51:12 | 000,361,600 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/06/20 07:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008/06/20 07:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\tcpip.sys
[color=#A23BEC]< MD5 for: [2008/06/20 07:59:02 | 000,361,600 | ---- | M] (MICROSOFT CORPORATION) >[/color]
[2008/06/20 07:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[color=#A23BEC]< MD5 for: [2009/12/19 09:42:37 | 000,330,264 | ---- | M] (INTEL CORPORATION) >[/color]
[2009/12/19 09:42:37 | 000,330,264 | ---- | M] (Intel Corporation) -- C:\WINDOWS\NLDRV\001\iastor.sys
[2009/12/19 09:42:37 | 000,330,264 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\iaStor.sys
[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[color=#A23BEC]< MD5 for: CHANGER.SYS >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[color=#A23BEC]< MD5 for: HAL.DLL >[/color]
[2004/08/17 08:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[color=#A23BEC]< MD5 for: ISAPNP.SYS >[/color]
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008/04/14 04:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[2006/10/18 16:47:08 | 000,311,808 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\Audiodev.dll
[2010/03/10 00:43:04 | 001,025,024 | ---- | M] (Společnost Microsoft)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\browseui.dll
[2008/04/14 03:51:40 | 000,336,384 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\cscdll.dll
[2008/04/14 03:51:40 | 006,630,912 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\cscui.dll
[2008/04/14 03:51:40 | 000,025,600 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\davclnt.dll
[2008/06/20 13:49:25 | 000,147,968 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dnsapi.dll
[2008/04/14 03:51:40 | 000,014,336 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\drprov.dll
[2008/04/14 03:51:50 | 000,378,880 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\mstask.dll
[2008/04/14 03:51:52 | 000,011,776 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\netrap.dll
[2008/04/14 03:51:52 | 000,080,384 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\netui0.dll
[2008/04/14 03:51:52 | 000,245,760 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\netui1.dll
[2008/04/14 03:51:52 | 000,067,072 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\ntdsapi.dll
[2008/04/14 03:51:52 | 000,044,032 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\ntlanman.dll
[2006/10/18 16:47:18 | 000,284,160 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\PortableDeviceApi.dll
[2008/04/14 03:51:56 | 000,064,000 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\samlib.dll
[2009/06/25 04:27:37 | 000,056,832 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\secur32.dll
[2010/03/10 00:43:10 | 001,510,400 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shdocvw.dll
[2008/06/17 15:02:56 | 015,063,040 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shell32.dll
[2008/04/14 03:51:56 | 000,068,096 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shgina.dll
[2010/02/26 01:43:59 | 000,627,200 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\urlmon.dll
[2007/10/25 04:28:30 | 000,222,720 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\wmasf.dll
[2009/05/19 23:56:52 | 002,458,112 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\WMVCore.dll
[2006/10/18 16:47:22 | 002,605,056 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\WpdShext.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]
[color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]
[color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
[2009/12/19 15:10:51 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/12/19 15:10:51 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/12/19 15:10:51 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[2006/10/18 16:47:08 | 000,311,808 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\Audiodev.dll
[2010/03/10 00:43:04 | 001,025,024 | ---- | M] (Společnost Microsoft)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\browseui.dll
[2008/04/14 03:51:40 | 000,336,384 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\cscdll.dll
[2008/04/14 03:51:40 | 006,630,912 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\cscui.dll
[2008/04/14 03:51:40 | 000,025,600 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\davclnt.dll
[2008/06/20 13:49:25 | 000,147,968 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dnsapi.dll
[2008/04/14 03:51:40 | 000,014,336 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\drprov.dll
[2008/04/14 03:51:50 | 000,378,880 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\mstask.dll
[2008/04/14 03:51:52 | 000,011,776 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\netrap.dll
[2008/04/14 03:51:52 | 000,080,384 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\netui0.dll
[2008/04/14 03:51:52 | 000,245,760 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\netui1.dll
[2008/04/14 03:51:52 | 000,067,072 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\ntdsapi.dll
[2008/04/14 03:51:52 | 000,044,032 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\ntlanman.dll
[2006/10/18 16:47:18 | 000,284,160 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\PortableDeviceApi.dll
[2008/04/14 03:51:56 | 000,064,000 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\samlib.dll
[2009/06/25 04:27:37 | 000,056,832 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\secur32.dll
[2010/03/10 00:43:10 | 001,510,400 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shdocvw.dll
[2008/06/17 15:02:56 | 015,063,040 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shell32.dll
[2008/04/14 03:51:56 | 000,068,096 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\shgina.dll
[2010/02/26 01:43:59 | 000,627,200 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\urlmon.dll
[2007/10/25 04:28:30 | 000,222,720 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\wmasf.dll
[2009/05/19 23:56:52 | 002,458,112 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\WMVCore.dll
[2006/10/18 16:47:22 | 002,605,056 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\WpdShext.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[color=#A23BEC]< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >[/color]
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< End of report >
Kód: Vybrat vše
Folder::
c:\program files\Faronics
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"=-
Restore::
c:\windows\system32\ctfmon.exe
c:\windows\explorer.exe
c:\windows\system32\user32.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\winlogon.exe
Kód: Vybrat vše
:processes
explorer.exe
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\WINDOWS\system32\tmp22D.tmp
C:\WINDOWS\system32\tmp22C.tmp
C:\UsbFix
C:\Program Files\AVG
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
:Services
catchme
:commands
[Reboot]